CVE-2024-12247

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

01 Oct 2025, 18:21

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
First Time Mattermost mattermost Server
Mattermost
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
Summary
  • (es) Las versiones 9.7.x &lt;= 9.7.5, 9.8.x &lt;= 9.8.2 y 9.9.x &lt;= 9.9.2 de Mattermost no logran propagar correctamente las actualizaciones del esquema de permisos entre los nodos del clúster, lo que permite que un usuario conserve los permisos antiguos, incluso si se ha actualizado el esquema de permisos.

05 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-05 16:15

Updated : 2025-10-01 18:21


NVD link : CVE-2024-12247

Mitre link : CVE-2024-12247

CVE.ORG link : CVE-2024-12247


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-863

Incorrect Authorization